Path Traversal Vulnerability in Kirki Page Builder Plugin for WordPress
CVE-2026-15601
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-15601?
The Kirki Page Builder plugin for WordPress is susceptible to a path traversal vulnerability that can occur through its extract_zip_file function. This flaw affects all versions up to and including 6.0.13, allowing authenticated users with custom-level access or higher to potentially write arbitrary files on the server. The vulnerability arises from the improper handling of a user-supplied app src value, which is used to construct download URLs. As a result, crafted ZIP files could be extracted in unintended directories, facilitating remote code execution by malicious actors.
Affected Version(s)
Kirki β Freeform Page Builder, Website Builder & Customizer 0 <= 6.0.13